Phish Swims Past Email Security With Milanote Pages
#1
Information 
Quote:The Milanote app, billed as the “Evernote for creatives” by reviewers, has attracted the notice of cybercriminals who are abusing it to carry out credential-stealing campaigns that skate past secure email gateways (SEGs), researchers said.
 
Milanote is a tool for organizing and collaborating on creative projects. Users can arrange their projects into handy visual boards that can be shared and collaboratively edited, with the ability to add notes, images, links, files and so on. It counts several heavy hitters as customers, including Chanel, Facebook, Google, Nike and Uber, among many others.
 
According to analysis from Avanan released Thursday, attackers are looking to hook victims by starting off with a simple email. It has the subject line, “Invoice for Project Proposal.” The email body is pretty bare-bones, saying only, “Hello. See attached invoice for the above referenced project. Please contact me if you have questions or need additional information. Thank you.” It doesn’t contain any personalization, logos or other social-engineering aspects.
 
“The email itself is pretty standard issue,” Gil Friedrich, CEO and co-founder of Avanan, told Threatpost in an interview. “It gets attention with the subject of ‘Invoice for Project Proposal.’ It’s certainly not the most sophisticated effort in the world, however, it understands what emails can get past static scanners, including, in this case, Milanote.”
 
Should a target open the attachment, a document opens that contains one line (“I have shared a file with you. Please click link[s] below to download”) followed by a clickable button that says “Open Docs.”
 
If the person clicks the button, they’re taken to a page hosted in the Milanote service:
Clicking this final link takes the target to a phishing page that attempts to harvest various types of credentials, researchers said.

Read more: Phish Swims Past Email Security with Milanote Pages | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Phish Swims Past Email Security With Milanote Pages - by silversurfer - 23 July 21, 12:22

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Geekbench flags Intel Binary Optimizatio...
Geekbench Browser ...harlan4096 — 07:41
AMD adds GFX1171 and GFX1172 to its “RDN...
AMD RDNA 4m aka RD...harlan4096 — 07:39
Intel introduces Core Ultra Series 3 vPr...
Intel Core Ultra S...harlan4096 — 07:38
Intel launches Arc Pro B70 at $949 with ...
Intel launches Arc...harlan4096 — 07:36
Google Rolls Out Android Auto Update To ...
Google has begun r...harlan4096 — 07:34

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (46)qaqapeti

[-]
Online Staff
There are no staff members currently online.

>